Pain Point Finder

Security checks across malware telemetry and agentic risk

Overview

The skill appears to do the disclosed job of researching Reddit pain points and does not show evidence of hidden persistence, privilege use, or unrelated data access.

Use this for market or product research, but remember outputs may include third-party Reddit content. Prefer summaries over long quotes, avoid storing unnecessary personal details, and redact usernames or sensitive details before sharing results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The plan explicitly extracts and returns Reddit post excerpts, comment quotes, and other third-party user-generated content without any privacy notice, minimization rules, or handling guidance. Even though Reddit content is publicly accessible, repackaging and surfacing quotes at scale can increase privacy risk, expose sensitive personal details, and create downstream compliance or trust issues for users of the skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal